Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Hyperlink NFT Extension

gilmlbeecofjmogfkaocnjmbiblmifad
Risk Score
5.28
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 1,000
Rating 5.0
Last updated 2023-06-08
Manifest version MV3
CSP present ✅ yes
Developer kaikaikangkang@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
  • Extension stale ~25 months; no updates since June 2023.
  • Developer uses free Gmail address with no verifiable business identity.
  • Content script injected into all twitter.com pages broadens attack surface for any future compromise.
  • Two innerHTML DOM-XSS sinks present; CSP does not include trusted-types or nonce protection.

Evidence

  • privacy_policy_generic_google store Privacy URL points to myaccount.google.com/privacypolicy — generic Google policy, not scoped to this extension. scope_extension=false, third_party_sharing=true.
  • developer_free_webmail store Developer email kaikaikangkang@gmail.com — free webmail, no verifiable business domain.
  • stale_extension store Last updated June 8 2023; ~25 months since update. MV3 but no active maintenance signals.
  • content_script_twitter manifest content_scripts injected on *://*.twitter.com/* — broad social platform reach for 1000-install NFT extension.
  • dom_xss_sinks crx Two innerHTML-from-variable findings: fontawesome.min.js and assets/index.e60fe6e6.js. CSP present but no trusted-types.
  • react_16_bundled crx React 16.13.1 bundled — below 16.14 patching threshold; no CVEs flagged in cve_findings_raw.
  • js_external_hosts crx JS contacts app.parami.io and reactjs.org; both single-country US, no bad-host hits.
  • no_verified_publisher store verified_publisher=false, is_featured_by_google=false, no recognized org. Reputation floor applies.

Permissions Breakdown

  • storage low Stores local extension state; limited blast radius.
  • tabs medium Can read tab URLs and titles; moderate info-disclosure risk.
  • content_scripts(*://*.twitter.com/*) medium Injects JS into all Twitter pages; can read/mutate page content.
  • content_scripts(https://app.parami.io/*) low Scoped to developer's own domain; narrow surface.

Pillar Scores

Permissions2.30
Reputation7.00
Network0.00
Webstore3.00
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 06:07
Listing SHA 1c69deb2f72c…
Force block — not fired
Score recovered no
Elapsed 25.8s